AI 中文总结
研究大规模安全运营中事件优先级排序问题,提出自适应事件优先级排序算法AIP,通过将事件表示为安全组件集合来适应多租户队列设置,在多方面评估中表现良好,还扩展数据集助力相关研究。
AI 中文摘要
大型安全运营中心(SOC)每天常面临数百起活跃事件,给分析师带来巨大认知和操作需求。事件通常按到达时间、粗略严重程度或特定产品启发式排序,相对优先级不明。我们引入了自适应事件优先级排序(AIP),它是微软Defender队列助手背后的排序算法,能持续为分析师调查对安全事件进行优先级排序。AIP通过将每个事件表示为从警报和元数据中提取的标准化安全组件集合,使BM25风格排序适应无查询、多租户队列设置。该模型结合了饱和局部组件频率、跨租户估计的全局组件稀有性、有界域先验乘数和组件级解释。在数万个客户中部署,AIP进行近实时推理,事件分数刷新中位延迟为5秒。在对1000个客户组织的专家评审评估中,AIP的Precision@10达到92.8%。在473,000个组织日队列的发布后遥测中,相对于严重程度排序,AIP将警报细节交互提高了5.8%,警报细节视图事件提高了17.5%。我们还扩展了微软GUIDE数据集,提供了首个用于SOC队列优先级排序的真实世界事件公共标签源,涵盖499个组织队列和9980个带有专家得出的优先级标签的事件,有助于研究社区开发、比较和推进事件优先级排序方法。
英文摘要
Large security operations centers (SOCs) often face hundreds of active incidents per day, creating substantial cognitive and operational demands for analysts. Analysts must quickly decide which incidents deserve attention within long, constantly changing queues, yet incidents are commonly ordered by arrival time, coarse severity, or product-specific heuristics that leave their relative priority unclear. We introduce Adaptive Incident Prioritization (AIP), the ranking algorithm behind Microsoft Defender Queue Assistant, which continuously prioritizes security incidents for analyst investigation. AIP adapts BM25-style ranking to a query-less, multi-tenant queue setting by representing each incident as a collection of normalized security components extracted from alerts and metadata. The model combines saturated local component frequency, global component rarity estimated across tenants, bounded domain-prior multipliers, and component-level explanations. Deployed across tens of thousands of customers, AIP performs near-real-time inference and refreshes incident scores with a median latency of five seconds. In an expert-reviewed evaluation across 1,000 customer organizations, AIP achieves 92.8% Precision@10. In post-launch telemetry across 473,000 organization-day queues, AIP increases alert-detail interaction by 5.8% and alert-detail view events by 17.5% relative to severity ordering, providing behavioral evidence that model-ranked queues concentrate analyst engagement. We also extend the Microsoft GUIDE dataset with, to our knowledge, the first public label source for SOC queue prioritization over real-world incidents. The extension covers 499 organization queues and 9,980 incidents with expert-derived priority labels, enabling the research community to develop, compare, and advance methods for incident prioritization.